LEGAL & TRUST
Subprocessors and Service Provider Transparency Notice
Customers should know which providers process information for their service and what those providers do. KRAVIA maintains an actual, product-specific register rather than treating every possible vendor as already in use or every payment institution as a subprocessor.
1
Different provider roles
A subprocessor processes customer personal data on KRAVIA's behalf when KRAVIA is itself acting as a processor. A provider processing KRAVIA-controlled corporate information may instead be our processor. An independent payment institution, connected application or professional adviser may act as an independent controller for some purposes.
The same organization can have different roles for different processing. The register identifies the actual service and relationship; a single broad label does not replace that analysis.
2
Information in the public register
Each relevant entry identifies the provider's legal name, function, affected product or service, general data categories, processing locations or meaningful location criteria, role and date of addition or last material review. AI entries also describe relevant training restrictions and retention arrangements. Details may link to a provider's privacy or contractual material when useful.
Security-sensitive architecture, credentials, detailed access paths and other customers' confidential information are not published. Location disclosure must consider storage, support and onward processing rather than only a provider's registered office.
3
Review before use
Providers are assessed proportionately for purpose, necessity, security, contractual protections, retention, incident assistance, international transfers and relevant subprocessors. AI providers must meet KRAVIA's private-content no-general-purpose-training commitment before receiving that content. An attractive price or free tier is not an exception to this requirement.
Only necessary information is shared and provider permissions are limited to the agreed function. Actual contract and configuration evidence is retained internally. Merely linking to a provider website is not due diligence.
4
Additions, replacements and objections
We update the register when a relevant provider changes. Where the DPA, enterprise contract or law requires advance notice and an objection opportunity, affected customers receive it through the agreed channel. An objection must be assessed for the particular processing and risk, and the parties seek a reasonable alternative or other appropriate resolution.
An emergency replacement needed for security or continuity follows any applicable contractual emergency process and is explained as soon as appropriate. It does not silently remove the customer's mandatory rights. The general public register is not a substitute for a contractual notification subscription or direct notice where required.
5
Connected applications chosen by customers
An application you independently connect is not automatically a KRAVIA-appointed subprocessor. The integration should explain the data and permissions exchanged, revocation controls and each party's role. KRAVIA still has responsibilities for its own integration and sharing decisions.
6
Requests and publication integrity
Contact privacy@kraviaprivatelimited.com for provider questions or the applicable DPA process. A register marked “requires verification” is an internal release blocker, not a public statement that KRAVIA has no providers. This notice must not be published as a substitute for the actual required list. Product vendors are not assumed to apply to the corporate site merely because KRAVIA operates that product.